ZeroHour

CVE-2021-41357

KEVmass

Local Privilege Escalation in Microsoft Win32k (Windows 10/11 and Server)

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
2%p80
Published
()
KEV added
AI analysis

CVE-2021-41357 is an elevation-of-privilege vulnerability in the Microsoft Win32k kernel component, rated 7.8 (high) with a local attack vector, low privileges required, and no user interaction needed. It is triggered by an attacker who already has a foothold as a low-privileged local user (for example after phishing or by chaining with another exploit) executing code that reaches the vulnerable Win32k code paths. Successful exploitation yields elevated kernel-level privileges with high impact on confidentiality, integrity, and availability, effectively giving the attacker full administrative control of the host. Affected systems include Windows 10 versions 2004, 20H2, and 21H1, Windows 11 21H2, and Windows Server versions 2004, 20H2, and 2022. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-04-25, confirming exploitation in the wild; no public proof-of-concept is known and ransomware usage is unconfirmed, while EPSS estimates a 2.1% chance of exploitation in the next 30 days.

What to do: Apply the October 2021 Microsoft Patch Tuesday security updates (or later cumulative updates) per Microsoft's instructions for every affected Windows 10, Windows 11, and Windows Server build, as required by the CISA KEV listing. Because this is a local privilege escalation, prioritize patching hosts where untrusted users or processes get local code execution, such as VDI, remote desktop servers, and shared workstations, and verify each host's installed cumulative update level. As a Win32k EoP flaw there is no widely documented workaround in the data, so patching is the primary remediation.

Affected
Microsoft Windows 102004, 20H2, 21H1
Microsoft Windows 1121H2
Microsoft Windows Server2004, 20H2, 2022
Estimated exposure
masshundreds of millions of endpoints and servers (affected Windows 10/11 builds were the mainstream Windows deployments at the time of the October 2021 patch) — Public operating-system market-share data showed Windows 10 2004/20H2/21H1 and the initial Windows 11 release dominating the Windows installed base in late 2021, implying exposure on the order of hundreds of millions of devices, with the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Win32k Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 2004, windows 10 20h2, windows 10 21h1, windows 11 21h2, windows server 2004, windows server 2022, windows server 20h2
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news